Back to skill

Security audit

Apollo

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Apollo.io API helper that sends user-provided queries to Apollo with a user-provided API key and shows no hidden execution or unrelated data handling.

Install only if you are comfortable sending prospecting searches, domains, and enrichment requests to Apollo.io using your Apollo API key. Use a least-privileged key where possible, verify APOLLO_BASE_URL before use, and keep the local apollo.env file private and limited to trusted variable assignments.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs users to send search terms, domains, and enrichment data to Apollo.io's external API without warning that potentially sensitive business or personal contact data will leave the local environment. This can lead to unintended disclosure of proprietary prospecting data, personal data, or internal research queries to a third-party service, especially in enterprise environments where users may assume local-only processing.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.